Secure Your Reseller Account: Two-Step Verification, PIN and Device Control
A reseller account holds real money and can move it in seconds. These steps take about ten minutes and remove most of the risk.
With it on, a stolen password alone is not enough — a code from your phone is also required. Three options are usually available:
Choose the authenticator app if you can. Google Authenticator, Authy and Microsoft Authenticator all work.
When you scan the QR code you are also shown a text key. Write it down and keep it somewhere safe. If you lose the phone without it, only an administrator can get you back in.
Your PIN authorises transfers and profile changes. It is separate from your password for a reason — use a different value.
Avoid: 1234, 1111, your birth year, the last four digits of your phone number. These are the first things anyone tries.
Your panel lists every device that has signed in, with IP address, browser and time. Look at it monthly. Anything you do not recognise — an unfamiliar city, a browser you never use, a sign-in at 3am — block it and change your password immediately.
Every sign-in is recorded. Repeated attempts from an address you do not know mean somebody is trying your password. Change it before they succeed.
If you use the API, whitelist only the server addresses that need it. A key restricted to your own IP is close to worthless if stolen.
Every one of these is a scam, without exception. Someone claiming to be from support and asking for a code is stealing your account while you read it out.
Speed matters more than certainty. Act first, investigate afterwards.